New Botnet Campaign Exploits Ruckus Wireless Flaw

A critical vulnerability has been discovered in Linux-based Ruckus access points (APs) that allows remote attackers to take control of vulnerable systems.

Followed by CVE-2023-25717 and first discovered in February, the flaw has recently been exploited by a new botnet called AndoryuBot, according to a new advisory from Fortinet.

“[AndoryuBot] it contains DDoS attack modules for different protocols and communicates with its command and control server through SOCKS5 proxies,” explained Fortinet Senior Antivirus Analyst Cara Lin.

“Based on our IPS [intrusion prevention system] signature trigger count […] this campaign began distributing the current version sometime after mid-April.”

AndoryuBot uses the Ruckus vulnerability to gain entry to a device and then download a script for further dissemination. The particular variant spotted by Fortinet targeted Linux systems and was designed to infect different types of computer processors, including some used in smartphones, laptops and other electronic devices.

AndoryuBot uses a way to download itself called “curl”. However, Fortinet found a bug in the malware’s code that prevents it from running on some computers.

“Once a target device is compromised, AndoryuBot quickly extends itself and starts communicating with its C2 server using the SOCKS protocol,” Lin wrote. “Once the victim system receives the attack command, it launches a DDoS attack on a specific IP address and port number.”

According to Lin, AndoryuBot is quickly updated with more DDoS methods and waits for attack commands.

“Users should be aware of this new threat and actively apply patches to affected devices as soon as they become available,” Fortinet advised.

The warning provides IPS signatures for customers and indicators of compromise (IOC) for other system defenders to protect enterprises against threats identified in the exploit.

Its publication comes weeks after Akamai security researchers discovered a new DDoS botnet capable of launching attacks with data volumes reaching several Tbps.

